Skip to main content

CWE archive

CWE-83 CVEs

Programmatic archive

25 CVEs tagged with CWE-833 Critical, 7 High, 11 Medium, 4 Low, 0 Unrated.

CVE-2026-59727

Published Jul 27, 2026

Astro is a web framework for content-driven websites. In versions 3.10.0 through 7.0.3, when a transition:persist, transition:scope, or transition:persist-props directive is appli…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
21.1

CVE-2026-49276

Published Jul 9, 2026

Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the writer field in any blueprint allowed a scripting link to be included as the tar…

CVSS 7.4 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-58263

Published Jul 1, 2026

Jodit Editor is a WYSIWYG editor with written in pure TypeScript file and image editing capabilities. In versions prior to 4.12.28, the built-in clean-html sanitizer can be bypass…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-48591

Published Jun 17, 2026

Improper Neutralization of Script in Attributes in a Web Page vulnerability in pragdave earmark allows stored cross-site scripting via unescaped HTML attribute values. 'Elixir.Ea…

CVSS 4.8 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-53841

Published Jun 16, 2026

OpenClaw before 2026.5.12 contains a cross-site scripting vulnerability in exported session HTML that preserves unsafe javascript: and data: links in generated content. Attackers…

CVSS 2.1 · Low
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-53722

Published Jun 12, 2026

Nuxt is an open-source web development framework for Vue.js. Prior to versions 3.21.7 and 4.4.7, <NuxtLink> did not validate the URL scheme of values bound to its to or href props…

CVSS 5.1 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-45669

Published Jun 12, 2026

Nuxt is an open-source web development framework for Vue.js. From versions 3.4.3 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6, navigateTo() with external: true generates a s…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-8245

Published May 21, 2026

Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection. Concrete\Core\Legacy\Pagination builds pagination links by raw-inter…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-23516

Published Jan 21, 2026

CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.2.0 through 2.54.0, an attacker is able to execute arbitrary JavaScript in a…

CVSS 8.6 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-22849

Published Jan 21, 2026

Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor was allowing users to modify rich text fields with HTML wi…

CVSS 7.2 · High
evidence mentions
7
Buzz score
30.8
Vendor/product tagsBeta · best-effort

CVE-2025-11682

Published Oct 27, 2025

Stored cross-site scripting (XSS) vulnerability in the LMT Dashboard of the Perx Customer Engagement & Loyalty Platform allows an authenticated attacker to execute arbitrary JavaS…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-4615

Published Oct 9, 2025

An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system r…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-58746

Published Sep 8, 2025

The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashboards, time pickers, and dropdown menus. Prior to version 2.…

CVSS 9.0 · Critical

CVE-2025-0137

Published May 14, 2025

An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables a malicious authenticated read-write administrato…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-0125

Published Apr 11, 2025

An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables a malicious authenticated read-write administrato…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-9103

Published Mar 24, 2025

Improper Neutralization of Script in Attributes in a Web Page vulnerability in Forcepoint Email Security (Blocked Messages module) allows Stored XSS. This issue affects Email Secu…

CVSS 6.1 · Medium

CVE-2025-27145

Published Feb 25, 2025

copyparty, a portable file server, has a DOM-based cross-site scripting vulnerability in versions prior to 1.16.15. The vulnerability is considered low-risk. By handing someone a…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-26283

Published Feb 22, 2024

An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme. This vulnerability affec…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37908

Published Oct 25, 2023

XWiki Rendering is a generic Rendering system that converts textual input in a given syntax into another syntax. The cleaning of attributes during XHTML rendering, introduced in v…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-30958

Published Aug 3, 2023

A security defect was identified in Foundry Frontend that enabled users to potentially conduct DOM XSS attacks if Foundry's CSP were to be bypassed. This defect was resolved with…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32070

Published May 10, 2023

XWiki Platform is a generic wiki platform. Prior to version 14.6-rc-1, HTML rendering didn't check for dangerous attributes/attribute values. This allowed cross-site scripting (XS…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-39262

Published Nov 3, 2022

GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package, GLPI administrator can define rich-text content to be displayed o…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-14525

Published Sep 18, 2020

Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort
Showing 1-25 of 25 CVEsPage 1 of 1